search
menu
icon-carat-right
cmu-wordmark
×
Home
Notes
Search
Report a Vulnerability
Disclosure Guidance
VINCE
Carnegie Mellon University
Software Engineering Institute
CERT Coordination Center
Home
Notes
Search
Report a Vulnerability
Disclosure Guidance
VINCE
Home
Current:
Notes
CERT/CC Vulnerability Notes Database
Published
Public
Updated
ID
CVSS
Title
2026-05-20
2026-05-20
2026-05-20
VU#980487
Local privilege escalation in Linux Kernel (Dirty Frag)
2026-03-30
2026-03-26
2026-05-20
VU#221883
CrewAI contains multiple vulnerabilities including SSRF, RCE and local file read
2026-05-18
2026-05-18
2026-05-18
VU#777338
SGLang contains two remote code execution and one path traversal vulnerability
2026-05-11
2026-05-11
2026-05-12
VU#471747
dnsmasq contains several vulnerabilities, including attacker DNS redirect, privilege escalation, and heap manipulation
2026-05-11
2026-05-11
2026-05-11
VU#937808
Casdoor contains Arbitrary File Write vulnerability
2026-05-08
2026-05-08
2026-05-08
VU#260001
Linux kernel contains local privilege escalation vulnerability (Copy Fail)
2025-09-09
2025-09-09
2026-05-04
VU#461364
Hiawatha open-source web server has multiple vulnerabilities
2026-04-20
2026-04-20
2026-04-27
VU#915947
SGLang is vulnerable to remote code execution when rendering chat templates from a model file
2026-04-21
2026-04-21
2026-04-24
VU#414811
Terrarium contains a vulnerability that allows arbitrary code execution
2026-04-23
2026-04-23
2026-04-23
VU#748485
Unauthenticated configuration modification vulnerability in Central Office Services - Content Hosting Component
2022-08-11
2022-08-11
2026-04-22
VU#309662
Signed third party UEFI bootloaders are vulnerable to Secure Boot bypass
2026-04-22
2026-04-22
2026-04-22
VU#518910
Ollama GGUF Quantization Remote Memory Leak
2026-04-21
2026-04-21
2026-04-21
VU#890999
Radware Alteon has a reflected XSS vulnerability that can execute JavaScript in the host browser
2026-04-09
2026-04-09
2026-04-09
VU#536588
Multiple Heap Buffer Overflows in Orthanc DICOM Server
2026-03-12
2026-03-12
2026-04-07
VU#665416
SGLang (sglang) is vulnerable to code execution attacks via unsafe pickle deserialization
Previous
You're on page
1
2
3
4
246
Next
Sponsored by
CISA.
Download PGP Key
Read CERT/CC Blog
Learn about Vulnerability Analysis